{"id":"CVE-2026-47155","title":"vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls (CVE-2026-47155)","summary":"A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with speci…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","cvssSource":"vendor","cwe":["CWE-829","CWE-345"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI 3.3","affected":["ai_inference_server","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","ai_inference_server 3.3","enterprise_linux_ai 3.3"],"patched":["ai_inference_server 3.3","enterprise_linux_ai 3.3"],"published":"2026-06-22","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:14:40+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47155.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47155.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-47155"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491580"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47155"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47155"},{"url":"https://github.com/vllm-project/vllm/commit/d26a28ab033697f55a1414b5b0435de7cd6045b6"},{"url":"https://github.com/vllm-project/vllm/pull/42616"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gm"},{"url":"https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac"},{"url":"https://access.redhat.com/errata/RHSA-2026:59138"},{"url":"https://access.redhat.com/errata/RHSA-2026:59139"},{"url":"https://access.redhat.com/errata/RHSA-2026:60363"},{"url":"https://access.redhat.com/errata/RHSA-2026:62336"},{"url":"https://access.redhat.com/errata/RHSA-2026:62335"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2301.yaml"},{"url":"https://github.com/vllm-project/vllm"},{"url":"https://github.com/advisories/GHSA-3ww4-5jv9-j5gm"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00249,"epssPercentile":0.16574,"aliases":["GHSA-3ww4-5jv9-j5gm","PYSEC-2026-2301"],"ecosystem":"pip","ingestedAt":"2026-07-07T15:41:59.559Z","slug":"CVE-2026-47155","body":"## Overview\n\nA flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with specific revisions to still load dynamic code or other configuration files from an unpinned or default revision. This issue can lead to a supply-chain integrity compromise, where operators may unknowingly serve models with unreviewed or unintended behavior.\n\n## Vendor advisories\n\n- **RHSA-2026:59138** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59138)\n- **RHSA-2026:59139** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59139)\n- **RHSA-2026:60363** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60363)\n- **RHSA-2026:62336** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62336)\n- **RHSA-2026:62335** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62335)\n- **Red Hat VEX** · Moderate · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47155.json)\n\n**vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls** — rated Moderate by Red Hat. Released 2026-06-22, updated 2026-09-21.\n\nAffected:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat AI Inference Server 3.3\n- Red Hat Enterprise Linux AI 3.3\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2026:59138 https://access.redhat.com/errata/RHSA-2026:59138\nFor more information visit https://access.redhat.com/errata/RHSA-2026:59139 https://access.redhat.com/errata/RHSA-2026:59139\nFor more information visit https://access.redhat.com/errata/RHSA-2026:60363 https://access.redhat.com/errata/RHSA-2026:60363\n\nWorkarounds / mitigations:\n\n- Upgrade to a vLLM build containing the fix (>= 0.22.0) when available from Red Hat. Until then, only serve models from trusted registries, pin revisions explicitly, and review nested artifacts in model repositories before deployment.\n\n## Package advisory (CVE-2026-47155)\n\nAffected packages:\n\n- `vllm < 0.22.0`\n\nPatched in:\n\n- `vllm 0.22.0`\n\nSource: https://osv.dev/vulnerability/GHSA-3ww4-5jv9-j5gm","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}